boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-74

Weakness type CWE-74 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
90688713

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▅▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 82 · 2026-06 171 · 2026-07 134 · 2026-08 229 · 2026-09 254 · 2026-10 14

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2013-22519.8100.0KEVApache Struts
CVE-2023-2252710.0100.0KEVAtlassian Confluence Data Center and Server
CVE-2019-27259.8100.0KEVOracle WebLogic Server
CVE-2022-359149.8100.0KEVTeclib GLPI
CVE-2022-461699.8100.0KEVUnauthenticated Command Injection
CVE-2019-175587.599.9KEVApache Solr
CVE-2022-437698.899.9KEVHitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Element…
CVE-2025-2028110.099.9KEVCisco ISE API Unauthenticated Remote Code Execution Vulnerability
CVE-2022-279247.599.8KEVSynacor Zimbra Collaboration Suite (ZCS)
CVE-2020-174969.899.8KEVvBulletin vBulletin
CVE-2019-115819.899.7KEVAtlassian Jira Server and Data Center
CVE-2025-2033710.099.3KEVCisco ISE API Unauthenticated Remote Code Execution Vulnerability
CVE-2020-84688.893.3KEVTrend Micro Apex One, OfficeScan and Worry-Free Business Security Agents
CVE-2023-45482.198.3—SPA-Cart eCommerce CMS GET Parameter search sql injection
CVE-2026-100602.192.0—TRENDnet TEW-432BRP formSetRoute command injection
CVE-2026-100612.192.0—TRENDnet TEW-432BRP formWPS command injection
CVE-2026-796978.691.9—Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command in…
CVE-2026-186868.991.6—GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
CVE-2026-185997.391.1—GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
CVE-2026-825952.190.9—D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
itsourcecode142
sourcecodester125
code-projects80
codeastro41
edimax23
gl.inet19
mathurvishal14
trendnet12
microsoft9
ziroom9
adithyayelloju7
cisco7
d-link7
ibm7
nousresearch7